CVE-2013-1707: Buffer Overflow
Stack-based buffer overflow in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 allows local users to gain privileges via a long pathname on the command line to the Mozilla Maintenance Service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1707?
CVE-2013-1707 has a high severity rating due to the potential for privilege escalation.
How do I fix CVE-2013-1707?
To fix CVE-2013-1707, update Mozilla Firefox or Thunderbird to version 23.0 or later, or the latest ESR version.
What software is affected by CVE-2013-1707?
CVE-2013-1707 affects Mozilla Firefox versions before 23.0 and Thunderbird versions before 17.0.8.
Can local users exploit CVE-2013-1707?
Yes, local users can exploit CVE-2013-1707 through a long pathname on the command line to the Mozilla Maintenance Service.
Is there a workaround for CVE-2013-1707?
The best workaround for CVE-2013-1707 is to ensure that vulnerable versions of the software are removed or updated promptly.